Bidders Library Security - DISAI 240-110-8.pdf
PDF 74 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This instruction prescribes the Defense Information Systems Agency's policy and assigns responsibilities for information security. It applies to all DISA activities and the Joint Force Headquarters-Department of Defense Information Networks. The Director of DISA has delegated responsibility for implementing, ensuring compliance with, and administering the agency's information security program to the Chief of the Security Division within the Workforce Services and Development Directorate. Directors, executives, commanders and major organizational element chiefs must ensure the effective application of information security policies and procedures, appoint security managers, and ensure individuals with access to classified information are appropriately cleared. Security managers are responsible for implementing information security, conducting self-inspections and training, reporting security incidents, and serving as liaisons on security issues. Specific positions have been delegated authority for original classification at the Top Secret, Secret and Confidential levels.
The related solicitation seeks proposals for test, evaluation and certification services to support the Joint Interoperability Test Command under contract number HC102821R0006. The Defense Information Systems Agency is the contracting agency. Offerors should submit proposals by the specified date to be considered for award.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEFENSE INFORMATION SYSTEMS AGENCY
P. O. BOX 549
FORT MEADE, MARYLAND 20755-0549
DISA INSTRUCTION 240-110-8* 26 May 2017
SECURITY
Information Security (INFOSEC)
1. Purpose. This Instruction prescribes policy and assigns responsibilities for information security (INFOSEC).
2. Applicability. This Instruction applies to all Defense Information Systems Agency (DISA) activities and the Joint Force Headquarters – Department of Defense Information Networks (JFHQ-DoDIN).
3. Authority. This Instruction is published in accordance with the authority contained in Executive Order 13526, Classified National Security Information, December 2010, and DoD Manual 5200.01-M, Volumes 1 - 4, DoD Information Security Program, February 2012.
(In cases of conflict between DoD 5200.01-M and this Instruction, the DoD Manual takes precedence.)
4. Policy.
4.1 Appropriate protection will be provided by DISA personnel for classified information under their custody and control. All officials within DISA who hold command, management, or super-visory positions will ensure the implementation and management of information security within their areas of responsibility.
4.2 Information shall be classified only when necessary in the interest of national security and shall be declassified as soon as it is consistent with the requirements of governing national security directives.
4.3 Persons shall be allowed access to classified information only if they possess a valid and appropriate security clearance, have executed an appropriate nondisclosure agreement, and have a valid need-to-know for access in performance of a lawful and authorized governmental function.
(DoD Regulation 5200.2, Personnel Security Program, contains detailed guidance on personnel security investigation, adjudication, and clearance.)
4.4 Classified information shall be maintained only when it is required for effective and efficient operation of the organization or its retention is required by law or regulation.
4.5 Classified documents and material that constitute permanently valuable records of the government shall be maintained and disposed of in accordance with DoD Directive 5015.2, Records Management Program.
DISAI 240-110-8
4.6 Compliance with this Instruction is mandatory, and violators are subject to administrative or judicial sanctions, or both.
5. Delegation of Authority. The Director, DISA, has delegated responsibility for implemen-tation, compliance, and administration of Agency INFOSEC to the Workforce Services and Development Directorate (WSD) Chief, Security Division (MP6). The Security Division (MP6) will apprise the Director, WSD, and, if applicable, the Chief of Staff, of the Agency's security posture and the status of security infractions, incidents, and violations.
6. Responsibilities.
6.1 Directors, Executives, Commanders, and Chiefs of Major Organizational Elements.
These individuals shall:
6.1.1 Ensure the effective application of this Instruction and all information security policies and procedures.
6.1.2 Ensure individuals who have access to classified information are appropriately cleared, are aware of their security responsibilities, and are indoctrinated and proficient in security policies and procedures applicable to the performance of their duties.
6.1.3 Appoint, in writing, a Security Manager (SM) to implement INFOSEC and ensure the SM has the tools, resources, and training necessary to successfully oversee INFOSEC for their respective activity.
6.2 Workforce Services and Development Directorate (WSD) Chief, Security Division (MP6). The WSD Chief, MP6, will:
6.2.1 Oversee INFOSEC for the Agency.
6.2.2 Develop, publish, and provide annual awareness training and products to educate personnel on ways to protect classified information from loss or compromise.
6.2.3 Appoint a program manager to represent the Agency on all information security issues, matters, and concerns.
6.2.4 Ensure appropriate security briefings are conducted and documented through periodic visits to DISA activities or during security program assessments.
6.2.5 Develop individual training, as needed, to assist SMs in overseeing and maintaining INFOSEC for their respective activity.
6.2.6 Monitor, inspect, and conduct Security Program Reviews (SPRs) and Security Assistance Visits (SAVs) at locations responsible for classified activities. (A SAV will cover all areas required by DoD Regulations and any areas requested from the component. The results of a SAV will be reported to the head of the requesting component.)
6.2.7 Ensure annual self-inspections of all DISA components have been conducted.
6.2.8 Serve as the Agency point of contact (POC) for all mandatory declassification review actions.
6.2.9 Provide POCs and communicative tools to disseminate security information to DISA personnel.
7. Security Manager (SM) Duties. An SM will:
7.1 Provide the Security Division (MP6) with an updated Security Manager Appointment Letter within 5 business days of new appointment or removal from the position.
7.2 Serve as the activity focal point providing guidance and distribution of DoD and DISA policies on classification, declassification, downgrading, safeguarding, security violations, security education and training, management and oversight, destruction, transmission, and marking of national security information.
7.3 Conduct annual compliance self-inspections, in accordance with DoD 5200.01-M, Volumes 1 – 4, and this Instruction under the provisions of the Information Security Oversight Office (ISOO). (The ISOO will establish the procedures and timeline for conducting the annual self-inspection. [A copy of all annual self-inspections and any corrective action taken is to be forwarded to the Security Division (MP6) within 30 calendar days of completion.])
7.4 Access the Joint Personnel Adjudication System (JPAS) to facilitate the accurate validation of clearances and investigative status for employees and visitors.
7.5 Ensure personnel complete all required security education and training and meet any local training and/or mission requirements.
7.6 Attend scheduled Agency SM meetings, working groups, training sessions, and conferences.
7.7 Prepare a standard operating procedure (SOP) for activity situations not addressed in this Instruction and review and/or update at least annually. (An initial review copy is to be provided to the Security Division (MP6) prior to activity distribution and notify, in writing, when an annual review or update is completed.)
7.8 Conduct indoctrination, refresher, courier, and termination briefings and enter attendance and completion information in the DISA On-Line Training System (DOTS).
7.9 Conduct document reviews in preparation for the DISA Annual Clean-Out Day, scheduled by MP6, in order to reduce unnecessary classified holdings. (The review includes downgrading, declassifying, destroying, or returning documents to the originator.)
7.10 Conduct a Fundamental Classification Guidance Review (FCGR) at least once every 5 years. (The Office of the Under Secretary of Defense for Intelligence and ISOO will execute the FCGR under their provisions and focus on information outlined in Title 32, CFR, Parts 2001 and 2003, Classified National Security Information. [A detailed summary report of FCGR results is to be provided by an SM to MP6 for their respective activity within 30 days of completion.])
7.11 Immediately report all suspected and confirmed security incidents or violations to MP6 and serve as a POC on the status of ongoing preliminary inquiries and/or formal investigations.
7.12 Serve as a liaison, on the behalf of the Security Division (MP6), to collect and submit data on their respective activity's classification management system to support the annual Standard Form (SF) 311: Agency Security Classification Management Program Data, as outlined in E.O. 13526 and its implementing directives.
7.13 Manage activity courier authorization and prepare, issue, and control courier cards and appointment letters for director or commander approval.
7.14 Ensure activity personnel who handle classified information or material are aware of classified handling policies and procedures to include copying, marking, storing, transmitting, and destroying.
7.15 Serve as the activity focal point of original or derivative classification actions during the designated sampling period designated by the Director, ISOO. (A report will be requested annually by MP6 from each activity and a complete Agency response will be compiled and submitted by MP6 to ISOO.)
8. Original Classification Authority (OCA). Delegations of OCA shall be limited to the minimum required to administer E.O. 13526. Agency heads are responsible for ensuring designated subordinate officials have a demonstrable and continuing need to exercise this authority.
8.1 Delegation of an OCA shall be in writing and the authority shall not be redelegated except as provided in E.O. 13526. Each delegation shall identify the official by name or position title.
8.1.1 The positions to which original Top Secret classification authority has been delegated by the Deputy Secretary of Defense, in writing, are the Director, DISA; Vice Director, DISA;
Chief of Staff, DISA; and Director, Operations Center.
8.1.2 The positions to which original Secret or Confidential classification authority has been delegated are the positions identified in subparagraph 8.1.1 and the Commander, White House Communications Agency.
8.2 The indoctrination, to include the annual training requirement of DISA OCAs, will be accomplished by MP6, in accordance with E.O. 13526 and its implementing directives.
8.3 A database tracking all reviewed and approved classifications is to be maintained by the OCA or their designee. The database should include such fields as the organization making the request, date approved, date last reviewed, title of the document, and POCs.
MARK E. ROSENSTEIN
Colonel, USA Chief of Staff
*This Instruction replaces DISAI 240-110-8, 8 December 2011.
OPR: WSD – disa.meade.mps.mbx.mps-front-office@mail.mil DISTRIBUTION: Approved for public release. Distribution is unlimited.
| 2017-05-26T14:03:24-0400 | |
| ROSENSTEIN.MARK.ERIC.1078644431 |
File details come from the government source that posted it. Updated .